{"id":46981,"date":"2026-09-10T06:20:49","date_gmt":"2026-09-10T06:20:49","guid":{"rendered":"https:\/\/financialrush.com\/?p=46981"},"modified":"2026-09-10T06:20:49","modified_gmt":"2026-09-10T06:20:49","slug":"fake-trezor-warning-claims-25-of-devices-are-vulnerable-in-latest-phishing-campaign","status":"publish","type":"post","link":"https:\/\/financialrush.com\/?p=46981","title":{"rendered":"Fake Trezor Warning Claims 25% of Devices Are Vulnerable in Latest Phishing Campaign"},"content":{"rendered":"<p> \n<br \/><\/p>\n<p>Hardware wallet maker Trezor said its third-party provider was breached and warned users that an email titled &#8220;Critical Security Alert: STM32 Entropy Vulnerability&#8221; was not sent by the company but was instead a phishing attempt.<\/p>\n<p>The company urged users not to click any links.<\/p>\n<h2 id=\"trezor-phishing-scam\">Trezor Phishing Scam<\/h2>\n<p>In an update on X, Trezor <a href=\"https:\/\/x.com\/Trezor\/status\/2097786518110609620\">said<\/a> it had taken down the domain and was investigating how hackers accessed its legitimate domain. The phishing message in question attempted to convince users that a serious security flaw has been found in STM32 microcontrollers used in its devices. According to the fabricated warning, STM32 microcontrollers could generate recovery phrases without enough randomness, potentially putting users&#8217; funds at risk. The email further claims that as many as 25% of devices may be affected.<\/p>\n<p>The issue may not be limited to Trezor users, according to Casa CEO and co-founder Nick Neuman. He <a href=\"https:\/\/x.com\/Nneuman\/status\/2097788564335427955\">noted<\/a> that reports of similar messages have surfaced among people using the BitBox device as well.<\/p>\n<p>This isn&#8217;t the first time a third-party partner connected to Trezor has suffered a security breach. In August, the platform <a href=\"https:\/\/cryptopotato.com\/trezor-provider-shipmonk-breach-exposed-order-data-for-13689-hardware-wallet-customers\/\">disclosed<\/a> a similar security incident involving its logistics partner, ShipMonk, which compromised personal details tied to a large number of customers.<\/p>\n<p>The exposed information included contact and delivery data. An earlier disclosure put the number of affected individuals at 13,689. However, Trezor later <a href=\"https:\/\/cryptopotato.com\/trezor-breach-is-much-bigger-than-initially-thought-another-67000-customers-exposed\/\">confirmed<\/a> that roughly 67,000 additional US customers were impacted, which pushed the total to 80,689 people whose information was exposed.<\/p>\n<h2 id=\"hardware-concerns\">Hardware Concerns<\/h2>\n<p>A separate security test also <a href=\"https:\/\/donjon.ledger.com\/blog\/tropic01-laser-fault-injection\/\">raised<\/a> concerns about the TROPIC01 chip found in Trezor&#8217;s Safe 7 wallet. In June, Ledger&#8217;s Donjon researchers found that, with specialized equipment and physical access to a device, an attacker could interfere with the chip while it checks firmware.<\/p>\n<p>The researchers used a carefully focused 1064 nm laser to trigger faults during the boot and update process. This could allow modified firmware to run. Trezor, however, said the finding does not put users&#8217; funds at risk.<\/p>\n<p>Blockchain investigator ZachXBT has been pretty blunt about hardware wallets in the past. He had earlier <a href=\"https:\/\/cryptopotato.com\/zachxbts-hardware-wallet-criticism-ignites-debate-over-crypto-self-custody\/\">said<\/a> that all hardware wallets are &#8220;complete garbage&#8221; and that he wouldn&#8217;t use them for important transactions or to store funds, and suggested keeping a separate iPhone just for wallet use instead.<\/p>\n<p>The post <a href=\"https:\/\/cryptopotato.com\/fake-trezor-warning-claims-25-of-devices-are-vulnerable-in-latest-phishing-campaign\/\">Fake Trezor Warning Claims 25% of Devices Are Vulnerable in Latest Phishing Campaign<\/a> appeared first on <a href=\"https:\/\/cryptopotato.com\/\" rel=\"nofollow\">CryptoPotato<\/a>.<\/p>\n\n<br \/><a href=\"https:\/\/cryptopotato.com\/fake-trezor-warning-claims-25-of-devices-are-vulnerable-in-latest-phishing-campaign\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Hardware wallet maker Trezor said its third-party provider was breached and warned users that an email titled &#8220;Critical&hellip;\n","protected":false},"author":2,"featured_media":46982,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-46981","post","type-post","status-publish","format-standard","has-post-thumbnail","category-crypto","cs-entry","cs-video-wrap"],"_links":{"self":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts\/46981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=46981"}],"version-history":[{"count":0,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts\/46981\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/media\/46982"}],"wp:attachment":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=46981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=46981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=46981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}